MRV Communications In-Reach Console Servers Access Control Bypass Vulnerability
BID:14300
Info
MRV Communications In-Reach Console Servers Access Control Bypass Vulnerability
| Bugtraq ID: | 14300 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 18 2005 12:00AM |
| Credit: | Discovery is credited to Dr. Dirk Wetter <[email protected]>. |
| Vulnerable: |
MRV Communications In-Reach LX-8000S 3.5 MRV Communications In-Reach LX-4000S 3.5 MRV Communications In-Reach LX-1000S 3.5 |
| Not Vulnerable: | |
Discussion
MRV Communications In-Reach Console Servers Access Control Bypass Vulnerability
In-Reach console servers are affected by an access control bypass vulnerability.
Under certain circumstances, the vulnerable devices fail to verify port based access controls and allows a user to access any port or console.
This issue affects In-Reach LX-8000, 4000 and 1000 series devices running software version 3.5.0. Other models may be vulnerable as well.
In-Reach console servers are affected by an access control bypass vulnerability.
Under certain circumstances, the vulnerable devices fail to verify port based access controls and allows a user to access any port or console.
This issue affects In-Reach LX-8000, 4000 and 1000 series devices running software version 3.5.0. Other models may be vulnerable as well.
Exploit / POC
MRV Communications In-Reach Console Servers Access Control Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
MRV Communications In-Reach Console Servers Access Control Bypass Vulnerability
Solution:
Reportedly, the vendor has released software version 3.5.1 to address this issue. This could not be confirmed by Symantec. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, the vendor has released software version 3.5.1 to address this issue. This could not be confirmed by Symantec. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MRV Communications In-Reach Console Servers Access Control Bypass Vulnerability
References:
References: